Skip to content

Security: trydrift/drift

SECURITY.md

Security

Please do not report security vulnerabilities through public GitHub issues.

Use GitHub’s private vulnerability reporting (Security → Report a vulnerability) or submit a report directly at:

https://github.com/trydrift/drift/security/advisories/new

What to include

If possible, include:

  • the affected Drift surface (CLI, GitHub Action, webhook server, or VS Code extension) and version or commit;
  • the security boundary you believe can be bypassed;
  • reproduction steps;
  • the impact you believe is possible.

Response and disclosure

We aim to acknowledge vulnerability reports within 7 days and coordinate disclosure with the reporter.

We generally target disclosure within 90 days, depending on severity and remediation complexity.

Please do not publicly disclose a vulnerability before we have had a reasonable opportunity to investigate and address it.

See docs/trust-and-safety.md for the threat model Drift documents against itself.

There aren't any published security advisories